mirror of
https://codeberg.org/guix/guix.git
synced 2025-10-02 02:15:12 +00:00
services: hurd-vm: Disable password-based authentication for root.
With offloading to a childhurd is enabled, allowing password-less root login in the childhurd to anyone amounts to providing write access to the host’s store to anyone. Thus, disable password-based root logins in the childhurd. * gnu/services/virtualization.scm (%hurd-vm-operating-system): Change ‘permit-root-login’ to 'prohibit-password. * gnu/tests/virtualization.scm (%childhurd-os): Provide a custom ‘os’ field for ‘hurd-vm-configuration’. * doc/guix.texi (Virtualization Services): Remove mention of password-less root login.
This commit is contained in:
parent
100d71f8a1
commit
c3a19cc2ac
3 changed files with 15 additions and 7 deletions
|
@ -1080,7 +1080,7 @@ that will be listening to receive secret keys on port 1004, TCP."
|
|||
(openssh-configuration
|
||||
(openssh openssh-sans-x)
|
||||
(use-pam? #f)
|
||||
(permit-root-login #t)
|
||||
(permit-root-login 'prohibit-password)
|
||||
(allow-empty-passwords? #t)
|
||||
(password-authentication? #t)))
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue